# Configuring decode\_json\_fields using docker labels

**URL:** <https://discuss.elastic.co/t/configuring-decode-json-fields-using-docker-labels/203378>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [October 14, 2019, 5:05am UTC](https://discuss.elastic.co/t/configuring-decode-json-fields-using-docker-labels/203378 "2019-10-14T05:05:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![trajano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trajano/32/38853_2.png) [@trajano](https://discuss.elastic.co/u/trajano)\
**Post date:** [October 14, 2019, 5:05am UTC](https://discuss.elastic.co/t/configuring-decode-json-fields-using-docker-labels/203378/1 "2019-10-14T05:05:37Z")

</div>

I have a service which I am deploying to the swarm. Specifically for the Kibana logs

It has the following labels defined:

```
deploy:
  labels:
    co.elastic.logs/processors.1.decode_json_fields.overwrite_keys: "true"
    co.elastic.logs/processors.1.decode_json_fields.target: ""
    co.elastic.logs/processors.1.decode_json_fields.process_array: "true"

```

But I don't see it being parsed out.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/4/e45752d0efe3d37a2f2f8708feb99b0e4118609e.png)

---

<div class="post-metadata">

**Author:** ![trajano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trajano/32/38853_2.png) [@trajano](https://discuss.elastic.co/u/trajano)\
**Post date:** [October 14, 2019, 6:31am UTC](https://discuss.elastic.co/t/configuring-decode-json-fields-using-docker-labels/203378/2 "2019-10-14T06:31:43Z")

</div>

Further expanding this, I also found a `kibana`module but that didn't work either.

I have a filebeat service defined as (note I don't use configuration files).

```auto

  filebeat:
    image: docker.elastic.co/beats/filebeat:7.4.0
    deploy:
      mode: global
    networks:
      - default
    command:
      - -E
      - |
        filebeat.autodiscover.providers=[
          {
            type: docker,
            hints.enabled: true
          }
        ]
      - -E
      - processors={1:{add_docker_metadata:{host:unix:///var/run/docker.sock}}}
      - -E
      - output.elasticsearch.enabled=false
      - -E
      - output.logstash.enabled=true
      - -E
      - output.logstash.hosts=["logstash:5044"]
      - -d
      - autodiscover
      - -e
    user: root
    labels:
      co.elastic.logs/enabled: "false"
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - /var/lib/docker/containers:/var/lib/docker/containers:ro

```

Kibana is defined as

```auto
  kibana:
    image: docker.elastic.co/kibana/kibana:7.4.0
    environment:
      - SERVER_BASEPATH=/kibana
      - SERVER_REWRITEBASEPATH=true
    ports:
      - 5601:5601
    networks:
      - intranet
      - management-ui
    deploy:
      labels:
        intranet: "true"
        traefik.enable: "true"
        traefik.http.routers.kibana.entryPoints: http
        traefik.http.routers.kibana.middlewares: default
        traefik.http.services.kibana.loadbalancer.server.port: 5601
    # I also tried putting it in the deploy labels but no luck there either.
    labels:
      co.elastic.logs/enabled: "true"
      co.elastic.logs/module: kibana
      co.elastic.logs/fileset.stdout: log

```

Looking at the logs I do see

> [autodiscover] autodiscover/autodiscover.go:191 Generated config: map[**log** :map[enabled:true input:map[paths:[/var/lib/docker/containers/c6eb8339d51768277c9f62651381fc5f89cbd57a58f515cafc070540ddabe9b9/\*-json.log] stream:stdout type:container]] **module:kibana** ]

Which appear to indicate the Kibana module gets recognized, but I do not see the entries being parsed out in an expected fashion.

I also had `traefik` with the `apache` module and `elasticsearch` with the `elasticsearch` module but those didn't do anything either.

Basically I am trying to get to the same stage as @rocketraman in [Keeping `message` field intact with module parsing - #3 by rocketraman](https://discuss.elastic.co/t/keeping-message-field-intact-with-module-parsing/155452/3)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2019, 6:31am UTC](https://discuss.elastic.co/t/configuring-decode-json-fields-using-docker-labels/203378/3 "2019-11-11T06:31:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
